On a forum where Autorun was mentioned as a way to spread certain malware, there was replied that it's not effective as in Win7+ it's disabled by default and lower versions got it disabled through Windows update. Then there is a quote from a PCmag article:

This malicious use has become so common that Microsoft is disabling it by default. Users who apply the update will still see an AutoRun menu when they plug in a key, but it will not have any options for running programs off of the device. This is the behavior that Windows 7 has had from its release. Certain high-end, security-hardened USB keys will still have the old behavior, as will CDs and DVDs.